India processed over 18,000 crore UPI transactions in 2025, making it the world’s largest real-time payment ecosystem. That scale also makes it the world’s most attractive target for payment fraud.

New data from fraud intelligence firm BioCatch, published in July 2026, shows that SMS-based banking scams in India surged 146% in the first half of 2026 compared with the same period last year. Mobile fraud sessions increased 67% overall. On iOS devices, the rise was 86%. On Android, 35%.

These are not abstract numbers. Behind each percentage point is a working professional who clicked a link in what appeared to be a bank OTP message, a senior citizen who transferred savings after a call from “bank security”, a small business owner who scanned a fake QR code at a vendor fair.

As a cybersecurity researcher who has tracked India’s digital fraud landscape for over a decade, I want to break down exactly what is happening, why it is getting worse, and what every Indian digital payment user must do right now.


The Numbers Behind the Crisis

Before examining the attack vectors, the scale of the problem requires a factual baseline.

According to data compiled by the Indian Cyber Crime Coordination Centre (I4C) under the Union Home Ministry, India lost Rs 52,976 crore to cyber fraud over the six-year period from 2020 to 2025. Of that staggering figure, Rs 19,812 crore was lost in 2025 alone – nearly one-third of the six-year total incurred in twelve months.

In Rajasthan alone, cyber fraudsters stole Rs 387 crore between January 1 and July 12, 2026. The state had reported Rs 354 crore in losses in all of 2023. The pace has more than doubled.

The Reserve Bank of India and the National Payments Corporation of India (NPCI) confirmed that UPI-specific frauds jumped 85% in FY2024. In FY2023-24, there were 13.42 lakh UPI fraud cases resulting in losses of Rs 1,087 crore.

The fraud complexity is evolving alongside the volume. The BioCatch report notes that the median value of attempted fraudulent transfers rose 1.7 times per fraud session, while the average duration of fraud-related phone calls fell 31%. Fraudsters are spending less time on each victim but extracting significantly more per session. They have industrialised the operation.


Why India Is a Primary Target

India’s digital payment infrastructure is both a national achievement and a national attack surface.

The Unified Payments Interface serves over 400 million active users. The Jan Dhan-Aadhaar-Mobile (JAM) trinity, designed for financial inclusion, created the world’s largest database of linked biometric-bank-phone identities. Criminals exploiting these systems have three structural advantages:

  • Volume provides cover. With 18,000 crore transactions annually, even a 0.001% fraud rate represents enormous absolute numbers. Automated fraud detection cannot flag every anomalous transaction when the baseline volume is this high.
  • Digital literacy gaps remain severe. Smartphone adoption outpaced digital security education by at least a decade. A user who received their first smartphone recently and immediately began making UPI payments has no framework to distinguish a genuine OTP SMS from a crafted phishing message.
  • Organised criminal infrastructure is offshore. I4C data indicates that nearly 46% of India-targeting cyber fraud operations are run from criminal compounds in Cambodia, Myanmar and Laos. These are staffed operations with call scripts, money mule networks and CRM systems spanning multiple countries.

I have previously documented how the same offshore criminal networks targeting individual payment fraud victims also conduct large-scale institutional breaches. For context on the broader threat landscape facing India, see my earlier analysis of the DRDO data breach 2026 and the Hinduja Tech ransomware attack.


The Five Attack Vectors Responsible for Most Losses in 2026

1. Smishing – Fake SMS From Your Bank

Smishing (SMS phishing) is the single fastest-growing attack vector in 2026. The 146% surge documented by BioCatch reflects how extensively criminal groups have shifted from voice calls to text.

A typical smishing attack looks like this: the victim receives a message stating their bank account is locked, their UPI ID has been flagged, or their debit card will expire unless they verify immediately. The message contains a link to a site that looks identical to their bank’s mobile portal. They enter their credentials. The fraudster harvests them in real time and initiates a transfer.

Smishing is particularly effective because India’s major banks and NPCI still communicate via SMS. When victims receive a message from what appears to be an SBI, HDFC or ICICI sender ID, their guard drops.

The rule: Banks never embed login links in SMS messages. A genuine bank alert tells you a transaction occurred. It never asks you to click a link to prevent something.

2. UPI QR Code Manipulation

This vector targets merchants and small business owners. A fraudster replaces a merchant’s legitimate QR code with their own at a point of sale. Customers pay the fraudster, not the merchant.

A more common variant is the collect request fraud. The victim receives a UPI collect request with a message claiming they are receiving a refund or prize. They enter their UPI PIN – which is a debit action, not a receipt action. Their money transfers out.

3. Fake Customer Care Numbers

A significant number of search queries for “HDFC customer care number” or “Paytm helpline” return fraudulent numbers ahead of official ones – including via paid search placements. When victims call these numbers for a legitimate problem like a failed transaction, the fraudster asks them to download AnyDesk or TeamViewer. Once installed, the fraudster takes control of the device, initiates UPI transactions and transfers funds.

4. Investment Fraud via WhatsApp and Telegram

Investment scams account for approximately 75-77% of all money stolen in India’s cyber fraud ecosystem, according to I4C data. The mechanism consistently involves unsolicited WhatsApp or Telegram messages from someone claiming to represent a brokerage, fake profit screenshots, and fabricated testimonials from controlled accounts. When the victim tries to withdraw profits, the platform freezes and demands a “tax payment” to release funds – which never happens.

The use of deepfake videos of public figures to legitimise fake platforms is now mainstream. A homemaker in Bengaluru lost Rs 43.4 lakh after watching an AI-generated deepfake video of Union Finance Minister Nirmala Sitharaman promoting a fake investment scheme as government-endorsed. I detail the deepfake threat further in my companion post on digital arrest scams and the Supreme Court’s July 2026 directive.

5. OTP Bypass and SIM Swap

SIM swap fraud involves a criminal convincing a telecom operator to port the victim’s phone number to a new SIM under their control. Once they control the number, all OTPs and two-factor authentication messages go to them. Criminal networks have recruited employees at telecom retail outlets who process fraudulent port requests for a commission.


My Analysis: What Is Driving the 2026 Surge

Three structural shifts are compounding the underlying problem.

Fraud-as-a-Service. The dark web offers complete cyber fraud kits targeting India’s UPI ecosystem: phishing templates styled like SBI, ICICI and Kotak interfaces, call scripts in Hindi and regional languages, and money mule recruitment networks. A criminal with minimal technical knowledge can launch a smishing campaign for the cost of a few hundred rupees.

AI-Enhanced Social Engineering. Voice cloning technology can now run on a standard laptop. Fraudsters are using cloned voices of family members to call victims claiming to be in distress, needing an urgent transfer. These calls are convincing enough to fool people who have known the person for decades.

Regulatory Arbitrage. India’s I4C can freeze accounts within hours of a complaint via the 1930 helpline. But when criminal operations are run from Myanmar or Cambodia, cross-border recovery is functionally near-impossible. Criminals know this and have designed their operations accordingly. I have documented similar cross-border attribution challenges in the Krybit ransomware India analysis.


10 Cyber Hygiene Rules – Non-Negotiable for Every Indian Digital Payment User

These are not suggestions. These are controls that, if followed consistently, would prevent the majority of fraud cases I encounter in my research and legal work.

  1. Never click a link in any SMS claiming to be from a bank. Open your bank’s app directly from your phone’s app store or use a bookmarked URL. Banks do not send login links via SMS.
  2. Set a UPI transaction limit in your banking app. Most UPI-enabled apps allow you to cap the maximum per-transaction and daily limit. Set it to what you actually use, not the maximum.
  3. Never share your UPI PIN, OTP or CVV on any call, regardless of who the caller claims to be. These are one-way credentials. Your bank will never ask for them.
  4. Verify customer care numbers only from the back of your debit/credit card or the official bank website. Never search for them on Google without cross-checking against the official source.
  5. Enable transaction notifications via both SMS and email. Two channels means a second alert catches unauthorised transactions faster than one channel alone.
  6. Never download AnyDesk, TeamViewer or any remote access application at someone’s request. No legitimate bank, courier company or government agency asks you to do this.
  7. Before paying via QR code, verify the payee name on your UPI app before entering your PIN. The payee name displayed after scanning must match the vendor you intend to pay.
  8. For any investment opportunity received via WhatsApp or Telegram, verify the broker’s SEBI registration independently at sebi.gov.in. No regulated broker recruits via WhatsApp groups.
  9. Activate SIM swap alerts on your telecom account. Airtel, Jio and Vi all allow you to register an alternate contact for SIM change notifications.
  10. If you receive a UPI collect request, you are being asked to PAY, not receive money. Never accept an incoming UPI collect request from an unknown party under any circumstances.

What to Do If You Have Been Defrauded

Time is the most critical variable in fraud recovery. The I4C’s 1930 financial cyber helpline has a freeze mechanism that can halt transactions within minutes of a complaint if the call is made promptly.

Immediate steps:

  1. Call 1930 (National Cyber Crime Helpline) immediately. Do not wait. Even 30 minutes can be the difference between funds being frozen and being moved offshore.
  2. File a complaint at cybercrime.gov.in (National Cyber Crime Reporting Portal).
  3. Block your card and disable UPI through your banking app.
  4. Report the fraud to your bank’s fraud team directly.
  5. File an FIR at your nearest police station and reference your cybercrime.gov.in complaint number.

The I4C has reported saving Rs 7,130 crore across 23 lakh complaints since the 1930 helpline launched. The system works, but only if you call within the golden window.


The Policy Gap That Must Be Closed

India’s Bharatiya Nyaya Sanhita 2023 contains provisions applicable to cyber fraud, but they are scattered. The specific mechanics of UPI fraud, smishing and AI-enhanced social engineering are not addressed with the precision they require.

What is needed is a dedicated Digital Financial Fraud Act that defines UPI fraud, smishing and SIM swap as specific criminal acts with graded punishments, creates mandatory bank liability for inadequate transaction monitoring, establishes fast-track courts for cyber fraud cases, and formalises asset-freezing protocols between I4C and commercial banks within defined SLAs. India has the infrastructure to be the most digitally safe large economy in the world. Right now, that potential is being undermined by a legislation gap that organised crime exploits systematically.

The Supreme Court’s July 29, 2026 direction on digital arrest fraud, which I analyse in detail in my companion post, is a step in the right direction – but it addresses the extortion dimension of cyber crime, not the payment fraud dimension. Both require distinct legislative attention.


If you found this analysis useful, share it with at least one person who makes digital payments – which is almost every working Indian today. The most effective cyber hygiene intervention is community awareness.

Report all cyber fraud at cybercrime.gov.in or call 1930. The helpline is available 24/7.